OSX.Macontrol Technical Details | Symantec
The Trojan may arrive on the compromised computer through spam emails and phishing emails.
When the Trojan is executed, it opens a back door on the computer computer by connecting to a remote location, which may include the ***owing IP address:
61.178.77.169
The remote attacker may perform the ***owing actions:
Close the connection to the remote location and end the threat
Collect information regarding the compromised computer and send it back to the remote server
Send the process list of the compromised computer to the remote server
End processes
Fork running processes
Retrieve the install path of the Trojan
Delete files
Run files
Send files to the remote server
Send user status and information to the remote server
Log out the current user
Put the compromised computer to sleep
Restart the compromised computer
Shut down the compromised computer
Luego no digáis que no sabíais nada.
He remarcado lo que me parece más peligroso.